MALICIOUS — 0399782ffa19aea1aab107707d3f1dce654cfff7e22fa7514a33cf9e21a37691
MALICIOUS — 0399782ffa19aea1aab107707d3f1dce654cfff7e22fa7514a33cf9e21a37691 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the RedLine family. 9 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0399782ffa19aea1aab107707d3f1dce654cfff7e22fa7514a33cf9e21a37691 - SHA-1:
e709c916c6dcb0a932cb9876b36f8c193f48bc33 - MD5:
91f7a0933ecc6d8c33ba3a699d8d8ad6 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - File type: pe · Size: 2447726 bytes
- Verdict: malicious (100/100) · Family: RedLine
Detections (9 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.91
- Microsoft Defender: Virus:Win32/Sivis.A
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Trellix Stinger (McAfee): PolyPatch-UPX
- Kaspersky (KVRT): Virus.Win32.Agent.es
MITRE ATT&CK
Dynamic analysis (windows)
20276 behavior events · 1 ATT&CK techniques · 96 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- settings-win.data.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/12431/files/e9f5e9bb0b18f1af9b0c655c98ebc6d06218f1e1fd359edc96f33d250a9ecc18 —
e9f5e9bb0b18f1af9b0c655c98ebc6d06218f1e1fd359edc96f33d250a9ecc18 - /opt/CAPEv2/storage/analyses/12431/files/3f8739ff0141607879723cbc9a792cddc82ce24e9a76e98c403ed4734be49e04 —
3f8739ff0141607879723cbc9a792cddc82ce24e9a76e98c403ed4734be49e04 - /opt/CAPEv2/storage/analyses/12431/files/fd4cb9e98e5586bcc89a581ec564b00e1fefedcbce724a1b423d716ba0968eb0 —
fd4cb9e98e5586bcc89a581ec564b00e1fefedcbce724a1b423d716ba0968eb0 - /opt/CAPEv2/storage/analyses/12431/files/4e9fdf5c70ef6144c9edd03374e4bdfa4f80971c0940120cdf75e7d57f2c7b64 —
4e9fdf5c70ef6144c9edd03374e4bdfa4f80971c0940120cdf75e7d57f2c7b64 - /opt/CAPEv2/storage/analyses/12431/files/111ae450d0b606a981bac29079ba73e966f284c2353103bc5d0bdae642a6f15c —
111ae450d0b606a981bac29079ba73e966f284c2353103bc5d0bdae642a6f15c - /opt/CAPEv2/storage/analyses/12431/files/ca40d9fc1ed910b89c2d5158d9712094c5029930981c1a19b25a9e4e68eb8d10 —
ca40d9fc1ed910b89c2d5158d9712094c5029930981c1a19b25a9e4e68eb8d10 - /opt/CAPEv2/storage/analyses/12431/files/30d9045a9f172208b13161d1f5204e5787e5e07bfbb4f490d0041b03b7f44f76 —
30d9045a9f172208b13161d1f5204e5787e5e07bfbb4f490d0041b03b7f44f76 - /opt/CAPEv2/storage/analyses/12431/files/860fdcafdaa6346f10214950f68994da715478f2ad4699d768d5a0cadaf43a9f —
860fdcafdaa6346f10214950f68994da715478f2ad4699d768d5a0cadaf43a9f - /opt/CAPEv2/storage/analyses/12431/files/db7676a30a1394d3bcdbda8f84885c8a923cae30cb93f9ff43237a2dfe4e8be5 —
db7676a30a1394d3bcdbda8f84885c8a923cae30cb93f9ff43237a2dfe4e8be5 - /opt/CAPEv2/storage/analyses/12431/files/b33e97cdba2686b5f345356209ea9459b3ef61bff44c8108a278f865f484fe51 —
b33e97cdba2686b5f345356209ea9459b3ef61bff44c8108a278f865f484fe51 - /opt/CAPEv2/storage/analyses/12431/files/558319bfb1e09896e6dbb8e98ec03f83fafa9669e81d9acd298ff9eec4e644c2 —
558319bfb1e09896e6dbb8e98ec03f83fafa9669e81d9acd298ff9eec4e644c2 - /opt/CAPEv2/storage/analyses/12431/files/734a1d86bbbf213de237ed5eac9dafb8884a18bd2d8824da66f7e134a400578e —
734a1d86bbbf213de237ed5eac9dafb8884a18bd2d8824da66f7e134a400578e - /opt/CAPEv2/storage/analyses/12431/files/e6746f87a75a96924b115db70419ef5de6555361b330ed222a3eeb4a7c34cf8e —
e6746f87a75a96924b115db70419ef5de6555361b330ed222a3eeb4a7c34cf8e - /opt/CAPEv2/storage/analyses/12431/files/2e6ff1780ddb59b1c8104520466644e576cb0bbd68f7fc838d875b22bbe6fd5d —
2e6ff1780ddb59b1c8104520466644e576cb0bbd68f7fc838d875b22bbe6fd5d - /opt/CAPEv2/storage/analyses/12431/files/6b59fa7b93e1bb3ecb84f4b86dbb6eca310491ba03e7c742af0562870e4de672 —
6b59fa7b93e1bb3ecb84f4b86dbb6eca310491ba03e7c742af0562870e4de672
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.adobe.com/go/reader_system_reqs_it.UnmoveFilesRimozione
- http://www.adobe.com/go/reader_system_reqs_it
- https://www.digicert.com/CPS0
- http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
- http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
- http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
- http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
- http://www.digicert.com/ssl-cps-repository.htm0
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
- http://mozilla.org/MPL/2.0/
- http://www.w3.org/TR/css3-text/
- http://www.w3.org/2003/g/data-view#
- http://www.w3.org/1999/xhtml
- http://www.w3.org/2001/XMLSchema-instance
- http://www.w3.org/2001/XMLSchema
- http://www.w3.org/2002/xforms
- http://www.w3.org/2001/xml-events
- http://www.w3.org/1998/Math/MathML
- http://openoffice.org/2004/office
- http://openoffice.org/2004/writer
Embedded domains
- creativecommons.org
- geocities.com
- www.adobe.com
- helpx.adobe.com
- www.microsoft.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
- cacerts.digicert.com
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- mozilla.org
- piwik.documentfoundation.org
- www.w3.org
- openoffice.org
- purl.org
- gmail.com
- wiki.documentfoundation.org
Embedded IP addresses
- 26.2.4.2
- 20.165.94.46
- 40.84.97.4
- 20.184.175.6
- 142.250.183.46
- 52.123.252.247
- 4.230.171.124
- 20.42.179.204
- 52.230.60.54
- 74.178.76.128
- 20.42.73.25
- 74.178.76.54
- 20.184.175.3
- 135.233.45.222
- 74.178.76.44
- 203.26.79.13
- 52.123.252.248
- 172.178.240.162
- 52.110.12.32
- 52.110.12.2
- 172.66.2.5
- 74.178.232.29
- 52.148.114.188
- 72.145.35.100
- 52.110.12.48
More RedLine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report